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DCID No. 1/16 


Director of central intelligence directive no. 1/1 6 

SECURITY OF FOREIGN INTELLIGENCE IN AUTOMATED 
DATA PROCESSING SYSTEMS AND NETWORKS 


(Effective 6 June 1978) 

Pursuant to Section 102 of the National Security Act of 1947, Executive Order 
12036, and National Security Council Intelligence Directives, and in order to ensure 
uniform protectionxof classified foreign intelligence, and foreign counterintelligence 2 
involving sensitive intelligence sources and methods, processed and/or stored in 
Automated Data Proofing (ADP) systems and networks, minimum security require- 
ments are hereby established. 

The diversity and comtolexity of such computer systems now in place in the 
Community and those already designed for future placement may not provide for 
compliance with the requirements of the directive in their entirety. Recognizing both 
the validity of the requirements and the difficulty involved in their application to 
currently installed and already ^designed ADP systems, the extent to which the 
exceptions to this Directive are applied to such systems is left to the determination of 
each National Foreign Intelligence Board (NFIB) member in view of his ultimate 
responsibility for the protection of intelligence information, 

1. Applicability 

This Directive shall apply to NFIB member agencies and all other United States 
Government departments and agencies whusdi process and/or store intelligence 
information in ADP systems and networks. It shddl apply equally when ADP systems 
and networks are owned and/or operated by the Upited States Government or by its 
contractors or consultants. 

2. Responsibilities 

Each NFIB member or his designee is responsible for ensuring compliance by his 
respective organization and any other organization for \vhich he has security 
responsibility with the provisions of this Directive and tnte attached Computer 
Security Regulation. The NFIB member or his designee may delegate this responsibil- 
ity as he deems appropriate except only the NFIB member ma\accredit an ADP 
system or network for operation in the Compartmented Mode. 

3. Policy 

A formal ADP security program shall be established and maintained! to ensure 
that intelligence information processed and/or stored by ADP systems and networks is 


1 Supersedes DCID 1/16, effective 18 May 1976. 
s Foreign intelligence and foreign counterintelligence are used in this Directive as defined in Sechxm^i. 
Executive Order 12036, and as classified under the provisions of Executive Order FI 65 ft For the purpose of 
this Directive, the term “intelligence information” shall include both foreign intelligence and fora 
counterintelligence as so defined. 
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adequately protected. The minimum security requirements for the allowed modes of 
operation of ADP systems and networks are contained in the attached Computer 
Security Regulation. Additional ADP security measures and capabilities may be 
established if deemed appropriate. ADP systems involving foreign governments shall 
be addressed on a case-by-case basis by the NFIB members involved. 

4. Exceptions 

a. This Directive shall not apply to the ADP systems or networks that are used 
exclusively for telecommunications services. Such systems or networks are 
controlled by pertinent national policies and regulations. 

b. The NFIB member or his designee may temporarily exempt specific ADP 
systems under his jurisdiction from complete compliance with this Directive and 
attached Regulation when such compliance would significantly impair the 
execution of his mission. Chapter III of the attached Regulation governs when 
the ADP system being exempted is part of an ADP network as defined therein. 

An exemption shall be granted only when the NFIB member or his designee is 
confident that the other security measures in effect will adequately protect the 
intelligence information being processed. The NFIB member or his designee 
granting an exception shall strive for the earliest feasible attainment of complete 
compliance. No exception shall be granted which would allow personnel with less 
than a TOP SECRET clearance based on a background investigation to access an 
ADP system or network which contains Sensitive Compartmented Information 
(SCI). 3 

c. Nothing in this Directive or the Computer Security Regulation shall 
supersede or augment the requirements on the control, use, and dissemination of 
Restricted Data, Formerly Restricted Data, or Communications Security 
(COMSEC) related material as established by or under existing statutes, direc- 
tives, or Presidential policy. 

3 The term “Sensitive Compartmented Information” as used in this Directive is intended to include all 
information and materials bearing special Community controls indicating restricted handling within present 
and future Community intelligence collection programs and their end products for which Community 
systems of compartmentation have been or will be formally established. 


STANSFIELD TURNER 
Director of Central Intelligence 
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